Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
July 28, 2026 More than 24,000 internet-exposed servers are leaking authentication password hashes through a 20-year-old vulnerability in their Baseboard Management Controller interfaces. Researchers at cybersecurity firm Lava discovered that…
Zimbra CVE: Russian Spies Exploit Zero-Click XSS
July 23, 2026 A Russian state-sponsored advanced persistent threat group known as Laundry Bear (also called Void Blizzard) has been silently reading Western mailboxes by exploiting a stored cross-site scripting vulnerability in Zimbra Collaboration…
South Korea Diplomat Data Breach
July 22, 2026 South Korea disclosed a major data breach on July 22, 2026, that exposed the personal information of current and former Ministry of Foreign Affairs employees. Hackers maintained access to the National Diplomatic Academy’s online…
Anubis Ransomware Attack on Coca-Cola and Fairlife
July 21, 2026 The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary. Consequently, the company was forced to suspend production at its U.S. facilities after attackers gained unauthorized access…
Abbott Laboratories Double Cyber Incident: ShinyHunters Claims PII Records Stolen in Vishing Attack
July 19, 2026 Abbott Laboratories, one of the world’s largest medical technology companies, is investigating two separate cybersecurity incidents disclosed this week. One involves the ShinyHunters extortion gang, which claims to have stolen more than 30…
Nihon Kotsu Cyberattack Shuts Down Japan Largest Taxi Fleet
July 14, 2026 Japan’s largest taxi operator, Nihon Kotsu, suffered a damaging cyberattack on July 12, 2026, forcing the company to shut down critical systems and suspend dispatch services across multiple cities. The incident highlights the growing…
Ghostcommit Prompt Injection Attack Steals Secrets via AI Code Review Blind Spot
July 11, 2026 Researchers from the University of Missouri Kansas City’s ASSET Research Group have disclosed a new supply-chain attack called Ghostcommit. This technique hides malicious prompt-injection instructions inside a PNG image embedded in an…
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
June 24, 2026 Cybersecurity researchers at Novee Security have disclosed a critical new class of CI/CD workflow vulnerabilities called Cordyceps. This flaw allows unauthenticated attackers to hijack GitHub Actions workflows and seize full control of…
Xsolis Data Breach Exposes 1.4 Million Patient Records in Healthcare AI Firm
June 23, 2026 Healthcare technology firm Xsolis disclosed a data breach on June 23, 2026, that compromised the personal and protected health information of nearly 1.4 million individuals. Furthermore, the incident began with a targeted phishing attack on…
Klue OAuth Breach: Icarus Group Exfiltrates Salesforce Data
June 22, 2026 Market intelligence platform Klue has confirmed a major security breach where attackers stole OAuth tokens used to connect customer Salesforce environments, enabling unauthorized data exfiltration from multiple organizations. The incident,…